Data breach
Healthcare Highways
- Records
- 4,924,677
- Breach date
- 4 August 2026Estimated
- Added
- 6 October 2026
What was exposed
7 types of data · 2 put you at serious risk
- Dates of birth4,924,677
- Names974,809
- Street addresses343,019
- Phone numbers124,208
- Social security numbers42,111
- Driving licence numbers23,020
- Email addresses3,447
About this breach
The ransomware group Chaos has claimed responsibility for stealing and publishing data belonging to Healthcare Highways, a Texas-based company that manages medical provider networks for employers and health plans. According to a listing on the group's leak site, mirrored by the dark web monitoring platform Ransomware.live, the group set a 24-hour deadline in early August 2026 for the company to make contact, then published what it claimed was 235 gigabytes of data after the deadline passed. The listing describes the cache as sensitive company and client records, and CyberVerso's eHealth Cyber Brief reported that the tranche reportedly includes protected health information from employee health plans and health insurance claims, along with internal corporate records. Healthcare Highways has not issued a public confirmation of the breach. Our investigation team indexed the leaked dataset and estimates it contains roughly 4.9 million rows of records tied to the company.
Limited public reporting: As of September 25, 2026, detailed company notices or major news coverage for this listing were limited in sources reviewed. The facts below rely primarily on the indexed fields plus any secondary sources cited.
Breach Timeline
August 4, 2026: Chaos listed Healthcare Highways on its leak site with a 24-hour countdown demanding contact from company representatives, according to Ransomware.live, which recorded the listing at 15:57 UTC that day.
August 5, 2026: Ransomware trackers recorded the publication of the claimed 235 GB data cache after the deadline expired, as reported by BreachSense and CyberVerso.
What Information Was Compromised?
Our analysis found the following data types in this breach: names (about 974,800 records), dates of birth (about 4.9 million records), street addresses (about 343,000), phone numbers (about 124,200), Social Security numbers (about 42,100), driver's license numbers (about 23,000), and email addresses (about 3,400). The dataset spans roughly 4.9 million rows overall, according to our investigation team.
Not every individual is affected by every type of data listed here.
The ransomware group's own posting did not specify data types, and Healthcare Highways has not published a notification describing what was taken. Because dates of birth, Social Security numbers, and driver's license numbers appear in the dataset, some individuals face exposure well beyond simple contact details.
What Are the Potential Risks for Affected Individuals?
A name combined with a date of birth, street address, and phone number gives fraudsters enough to open accounts, answer security questions, or impersonate someone convincingly. A Social Security number raises the stakes further, since it can support fraudulent credit applications, tax refund fraud, or bogus government paperwork. Driver's license numbers add another identity document that can be copied or misused.
Healthcare-related breaches carry a specific risk as well. When records connect to health plans or insurance claims, criminals can attempt medical identity theft, submitting fake claims or using someone's coverage. Affected people may also see more phishing emails or calls, because attackers use real names and details from a breach to appear legitimate.
What Should You Do If You Were Affected?
Consider taking these steps, whether or not Healthcare Highways confirms your data was involved:
Place a free fraud alert or security freeze with the three credit bureaus, Equifax, Experian, and TransUnion. A freeze blocks most new credit in your name.
Review your credit reports at annualcreditreport.com for accounts you did not open.
File your taxes early if you can, before a fraudster files a return using your Social Security number.
Watch explanation-of-benefits letters and insurance statements for care you never received, and dispute anything unfamiliar with your insurer.
Be skeptical of calls, texts, or emails that cite your personal details. Legitimate organizations will not ask for full Social Security numbers by phone.
Update passwords on email and financial accounts, and turn on multi-factor authentication where it is offered.
Because the company had not posted a public notification as of September 25, 2026, there is no confirmed list of affected individuals and no verified offer of credit monitoring. Check Healthcare Highways' website and your mail for any notice that may follow.
In the news
- Ransomware.live listing for healthcarehighways.comransomware.live (opens in a new tab)
- CyberVerso eHealth Cyber Brief, August 21, 2026cyberverso.net (opens in a new tab)
- ClassAction.org coverage of the alleged breachclassaction.org (opens in a new tab)
- BreachSense report on the Healthcare Highways listingbreachsense.com (opens in a new tab)
- GalaxyWarden summary of the Chaos leak-site postinggalaxywarden.com (opens in a new tab)
